Ask for the facts you need. Receive them already verified.

Collecting ID scans and certificates costs time, creates risk and annoys customers. With Bisotun you request specific items, such as "over 18" or "member of" from cards that organizations can issue, and receive them with a cryptographic proof that a trusted issuer vouches for them.

Developer integrationTry the live demo

What you gain

Less personal data to store

You receive the answer to your question, not a document full of details you never needed. What you do not hold cannot leak.

No manual document checks

No staff comparing photos and stamps. The issuer's signature is checked automatically and you get a clear valid / not valid result.

Faster onboarding

A customer approves one request in their wallet instead of filling in forms and uploading files, and you can decide immediately.

Login without passwords

Offer "Log in with Bisotun": no password database to protect, no reset emails, and no passwords for attackers to guess or reuse.

Fewer forgeries

An altered or invented card fails the signature check, and a copied card is useless without the owner's wallet and PIN.

Visible respect for privacy

Customers see exactly what you ask for. Asking only for what you need builds trust.

Collecting documents vs. requesting cards

Collecting ID copies and certificatesRequesting Bisotun cards
Customer uploads a full documentCustomer shares only the requested items
You store the file and must protect itYou store only what you decide to keep from the result
Staff check authenticity by eye, or contact the issuerThe issuer's signature is verified automatically in the session
Days of back-and-forth for unclear scansAn answer as soon as the customer approves
Separate usernames and passwordsPasswordless login with the customer's wallet

What you can request

Available today

The wallet's account ID: a random identifier, the same towards every service. Suitable for passwordless login to an account.

Coming soon

The verified email address, confirmed by Bisotun. The usual choice for login and sign-up once it is available.

When issuers issue them

Any card an organization issues on Bisotun: age, education, membership, employment and more. You can ask for single items, several items from several cards, alternatives ("student card or membership card"), optional items, or a specific value ("level: gold").

How a request works

  1. Your server builds the request

    It lists the items you need and signs the request with your key. The browser never sees your key and cannot change what is asked.

  2. Your page shows the Bisotun widget

    A QR code on computers, an "Open Bisotun Wallet" button on phones, in Persian, Arabic or English.

  3. The customer decides

    Their wallet shows who is asking and which items, and they share or decline.

  4. The proof is verified

    Bisotun's session server checks the issuer's signatures, the expiry dates and that the proof belongs to the customer's wallet.

  5. Your back end receives a signed result

    The result, signed by the session server, is posted to your server. You check the status and the items, then log the customer in or continue your process.

Getting started

  1. Contact us

    Write to support@bisotun.app with what you want to verify and why.

  2. Get registered

    You receive a requestor name, register your public key (or receive a shared secret), and get permission for exactly the items you need. Requests for anything else are refused.

  3. Integrate

    Add the widget and two or three endpoints on your server. See the developer guide.

  4. Test

    Use the demo, a sample service with passwordless login, to see the full flow from the customer's side.

Honest limits

  • Your name is not verified in the wallet yet. Customers see your web address with a notice that you are not a known organization. A registry of verified organization names is planned.
  • Bisotun's session server sees the result. It verifies the proof for you, so it handles the shared values; it keeps results in memory for up to five minutes and keeps no record of them.
  • Cards cannot be withdrawn early. A card stays valid until its expiry date; issuers choose the validity. Ask the issuer how often its cards are renewed if that matters to you.
  • Online and Android only. Customers need an Android phone with internet; offline and in-person NFC use are not supported.
  • Regulatory fit is your call. Whether a Bisotun check meets a specific legal identification requirement depends on your sector, your regulator and the issuer of the card.

Ready to replace document uploads?

Read the developer guideContact support@bisotun.app